2016-03-16 09:45:37 +00:00
|
|
|
#!/usr/bin/env python
|
|
|
|
|
|
|
|
import argparse
|
2018-10-20 11:16:55 +11:00
|
|
|
import getpass
|
2016-07-06 12:17:54 +09:00
|
|
|
import sys
|
2018-11-08 04:57:28 +11:00
|
|
|
import unicodedata
|
2016-07-06 12:17:54 +09:00
|
|
|
|
2016-03-16 09:45:37 +00:00
|
|
|
import bcrypt
|
2016-07-06 12:17:54 +09:00
|
|
|
import yaml
|
|
|
|
|
2018-11-08 04:57:28 +11:00
|
|
|
|
Disallow untyped defs in synapse._scripts (#12422)
Of note:
* No untyped defs in `register_new_matrix_user`
This one might be contraversial. `request_registration` has three
dependency-injection arguments used for testing. I'm removing the
injection of the `requests` module and using `unitest.mock.patch` in the
test cases instead.
Doing `reveal_type(requests)` and `reveal_type(requests.get)` before the
change:
```
synapse/_scripts/register_new_matrix_user.py:45: note: Revealed type is "Any"
synapse/_scripts/register_new_matrix_user.py:46: note: Revealed type is "Any"
```
And after:
```
synapse/_scripts/register_new_matrix_user.py:44: note: Revealed type is "types.ModuleType"
synapse/_scripts/register_new_matrix_user.py:45: note: Revealed type is "def (url: Union[builtins.str, builtins.bytes], params: Union[Union[_typeshed.SupportsItems[Union[builtins.str, builtins.bytes, builtins.int, builtins.float], Union[builtins.str, builtins.bytes, builtins.int, builtins.float, typing.Iterable[Union[builtins.str, builtins.bytes, builtins.int, builtins.float]], None]], Tuple[Union[builtins.str, builtins.bytes, builtins.int, builtins.float], Union[builtins.str, builtins.bytes, builtins.int, builtins.float, typing.Iterable[Union[builtins.str, builtins.bytes, builtins.int, builtins.float]], None]], typing.Iterable[Tuple[Union[builtins.str, builtins.bytes, builtins.int, builtins.float], Union[builtins.str, builtins.bytes, builtins.int, builtins.float, typing.Iterable[Union[builtins.str, builtins.bytes, builtins.int, builtins.float]], None]]], builtins.str, builtins.bytes], None] =, data: Union[Any, None] =, headers: Union[Any, None] =, cookies: Union[Any, None] =, files: Union[Any, None] =, auth: Union[Any, None] =, timeout: Union[Any, None] =, allow_redirects: builtins.bool =, proxies: Union[Any, None] =, hooks: Union[Any, None] =, stream: Union[Any, None] =, verify: Union[Any, None] =, cert: Union[Any, None] =, json: Union[Any, None] =) -> requests.models.Response"
```
* Drive-by comment in `synapse.storage.types`
* No untyped defs in `synapse_port_db`
This was by far the most painful. I'm happy to break this up into
smaller pieces for review if it's not managable as-is.
2022-04-11 12:41:55 +01:00
|
|
|
def prompt_for_pass() -> str:
|
2016-03-16 09:45:37 +00:00
|
|
|
password = getpass.getpass("Password: ")
|
|
|
|
|
|
|
|
if not password:
|
|
|
|
raise Exception("Password cannot be blank.")
|
|
|
|
|
|
|
|
confirm_password = getpass.getpass("Confirm password: ")
|
|
|
|
|
|
|
|
if password != confirm_password:
|
|
|
|
raise Exception("Passwords do not match.")
|
|
|
|
|
|
|
|
return password
|
|
|
|
|
2018-11-08 04:57:28 +11:00
|
|
|
|
Disallow untyped defs in synapse._scripts (#12422)
Of note:
* No untyped defs in `register_new_matrix_user`
This one might be contraversial. `request_registration` has three
dependency-injection arguments used for testing. I'm removing the
injection of the `requests` module and using `unitest.mock.patch` in the
test cases instead.
Doing `reveal_type(requests)` and `reveal_type(requests.get)` before the
change:
```
synapse/_scripts/register_new_matrix_user.py:45: note: Revealed type is "Any"
synapse/_scripts/register_new_matrix_user.py:46: note: Revealed type is "Any"
```
And after:
```
synapse/_scripts/register_new_matrix_user.py:44: note: Revealed type is "types.ModuleType"
synapse/_scripts/register_new_matrix_user.py:45: note: Revealed type is "def (url: Union[builtins.str, builtins.bytes], params: Union[Union[_typeshed.SupportsItems[Union[builtins.str, builtins.bytes, builtins.int, builtins.float], Union[builtins.str, builtins.bytes, builtins.int, builtins.float, typing.Iterable[Union[builtins.str, builtins.bytes, builtins.int, builtins.float]], None]], Tuple[Union[builtins.str, builtins.bytes, builtins.int, builtins.float], Union[builtins.str, builtins.bytes, builtins.int, builtins.float, typing.Iterable[Union[builtins.str, builtins.bytes, builtins.int, builtins.float]], None]], typing.Iterable[Tuple[Union[builtins.str, builtins.bytes, builtins.int, builtins.float], Union[builtins.str, builtins.bytes, builtins.int, builtins.float, typing.Iterable[Union[builtins.str, builtins.bytes, builtins.int, builtins.float]], None]]], builtins.str, builtins.bytes], None] =, data: Union[Any, None] =, headers: Union[Any, None] =, cookies: Union[Any, None] =, files: Union[Any, None] =, auth: Union[Any, None] =, timeout: Union[Any, None] =, allow_redirects: builtins.bool =, proxies: Union[Any, None] =, hooks: Union[Any, None] =, stream: Union[Any, None] =, verify: Union[Any, None] =, cert: Union[Any, None] =, json: Union[Any, None] =) -> requests.models.Response"
```
* Drive-by comment in `synapse.storage.types`
* No untyped defs in `synapse_port_db`
This was by far the most painful. I'm happy to break this up into
smaller pieces for review if it's not managable as-is.
2022-04-11 12:41:55 +01:00
|
|
|
def main() -> None:
|
2022-03-02 13:00:16 +00:00
|
|
|
bcrypt_rounds = 12
|
|
|
|
password_pepper = ""
|
|
|
|
|
2016-03-16 09:45:37 +00:00
|
|
|
parser = argparse.ArgumentParser(
|
2018-11-08 04:57:28 +11:00
|
|
|
description=(
|
|
|
|
"Calculate the hash of a new password, so that passwords can be reset"
|
|
|
|
)
|
|
|
|
)
|
2016-03-16 09:45:37 +00:00
|
|
|
parser.add_argument(
|
2018-11-08 04:57:28 +11:00
|
|
|
"-p",
|
|
|
|
"--password",
|
2016-03-16 09:45:37 +00:00
|
|
|
default=None,
|
|
|
|
help="New password for user. Will prompt if omitted.",
|
|
|
|
)
|
2016-07-06 12:17:54 +09:00
|
|
|
parser.add_argument(
|
2018-11-08 04:57:28 +11:00
|
|
|
"-c",
|
|
|
|
"--config",
|
2021-05-14 11:46:35 +01:00
|
|
|
type=argparse.FileType("r"),
|
2018-11-08 04:57:28 +11:00
|
|
|
help=(
|
|
|
|
"Path to server config file. "
|
|
|
|
"Used to read in bcrypt_rounds and password_pepper."
|
|
|
|
),
|
2022-05-19 14:03:13 +01:00
|
|
|
required=True,
|
2016-07-06 12:17:54 +09:00
|
|
|
)
|
2016-03-16 09:45:37 +00:00
|
|
|
|
|
|
|
args = parser.parse_args()
|
2022-05-19 14:03:13 +01:00
|
|
|
config = yaml.safe_load(args.config)
|
|
|
|
bcrypt_rounds = config.get("bcrypt_rounds", bcrypt_rounds)
|
|
|
|
password_config = config.get("password_config", None) or {}
|
|
|
|
password_pepper = password_config.get("pepper", password_pepper)
|
2016-03-16 09:45:37 +00:00
|
|
|
password = args.password
|
|
|
|
|
|
|
|
if not password:
|
|
|
|
password = prompt_for_pass()
|
|
|
|
|
2018-11-08 04:57:28 +11:00
|
|
|
# On Python 2, make sure we decode it to Unicode before we normalise it
|
|
|
|
if isinstance(password, bytes):
|
|
|
|
try:
|
|
|
|
password = password.decode(sys.stdin.encoding)
|
|
|
|
except UnicodeDecodeError:
|
|
|
|
print(
|
|
|
|
"ERROR! Your password is not decodable using your terminal encoding (%s)."
|
|
|
|
% (sys.stdin.encoding,)
|
|
|
|
)
|
|
|
|
|
|
|
|
pw = unicodedata.normalize("NFKC", password)
|
|
|
|
|
|
|
|
hashed = bcrypt.hashpw(
|
2021-05-14 11:46:35 +01:00
|
|
|
pw.encode("utf8") + password_pepper.encode("utf8"),
|
2018-11-08 04:57:28 +11:00
|
|
|
bcrypt.gensalt(bcrypt_rounds),
|
2021-05-14 11:46:35 +01:00
|
|
|
).decode("ascii")
|
2018-11-08 04:57:28 +11:00
|
|
|
|
|
|
|
print(hashed)
|
2022-03-02 13:00:16 +00:00
|
|
|
|
|
|
|
|
|
|
|
if __name__ == "__main__":
|
|
|
|
main()
|